Mac OS X : Java for OS X 2013-002

High Nessus Plugin ID 65028


The remote host has a version of Java that is affected by multiple vulnerabilities.


The remote Mac OS X 10.7 or 10.8 host has a Java runtime that is missing the Java for OS X 2013-002 update, which updates the Java version to 1.6.0_43. It is, therefore, affected by two security vulnerabilities, the most serious of which may allow an untrusted Java applet to execute arbitrary code with the privileges of the current user outside the Java sandbox.

Note that an exploit for CVE-2013-1493 has been observed in the wild.


Apply the Java for OS X 2013-002 update, which includes version 14.6.1 of the JavaVM Framework.

See Also

Plugin Details

Severity: High

ID: 65028

File Name: macosx_java_2013-002.nasl

Version: 1.12

Type: local

Agent: macosx

Published: 2013/03/05

Modified: 2017/05/30

Dependencies: 12634

Risk Information

Risk Factor: High


Base Score: 9.3

Temporal Score: 8.1

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:apple:java_1.6

Required KB Items: Host/local_checks_enabled, Host/MacOSX/Version

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2013/03/04

Vulnerability Publication Date: 2013/02/28

Exploitable With

Core Impact

Metasploit (Java CMM Remote Code Execution)

Reference Information

CVE: CVE-2013-0809, CVE-2013-1493

BID: 58238, 58296

OSVDB: 90737, 90837

APPLE-SA: APPLE-SA-2013-03-04-1